Tech Support Forum banner

Problems with Troj Vundo.CXJ and others

1192 Views 7 Replies 2 Participants Last post by  greyknight17
My pc is infected with a virus. I get a non-stop Trend Micro warning of [Troj Vundo.CXJ ddcArSJc.dll]. I have ran the Deckard's system scanner as well as a Panda Activescan. I believe it has disabled Windows Updates, the Windows Search option in the Start menu, and oddly Windows Media Player (when i click on it, WMP doesn't open...strange). This all started a few days ago. Any help will be much appreciated, thanks.

Deckard's System Scanner v20071014.68
Run by Mike & Michelle on 2008-06-07 10:18:06
Computer is in Normal Mode.
--------------------------------------------------------------------------------



-- HijackThis (run as Mike & Michelle.exe) -------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:18:08 AM, on 6/7/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\PcCtlCom.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\PcScnSrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\tmproxy.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\TOSHIBA\gigabeat room 3.0\TosGbWatcher.exe
C:\WINDOWS\system32\svdhost.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Mike & Michelle\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\MIKE&M~1.EXE

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {087080C2-CE44-4E75-982E-ABB69C63A176} - C:\WINDOWS\system32\tuvUlJYR.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: {b93be280-d448-20e9-e064-3927fdf3a0d7} - {7d0a3fdf-7293-460e-9e02-844d082eb39b} - C:\WINDOWS\system32\kfhcgsqk.dll
O2 - BHO: (no name) - {BDD714BC-D36C-487B-8142-8BA020FB6535} - C:\WINDOWS\system32\ddcArSJc.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [TosGbWatcher] "C:\Program Files\TOSHIBA\gigabeat room 3.0\TosGbWatcher.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Windows Sound] svdhost.exe
O4 - HKLM\..\Run: [Microsoft WinUpdate] C:\WINDOWS\system32\msupdte.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [44a07517] rundll32.exe "C:\WINDOWS\system32\oepsrcbf.dll",b
O4 - HKLM\..\Run: [BM4793468b] Rundll32.exe "C:\WINDOWS\system32\uyibarnf.dll",s
O4 - HKLM\..\RunServices: [Windows Sound] svdhost.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-21-73586283-1450960922-682003330-1005\..\Run: [OE] "C:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe" (User 'Ramsey & Heather')
O4 - HKUS\S-1-5-21-73586283-1450960922-682003330-1005\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Ramsey & Heather')
O4 - HKUS\S-1-5-21-73586283-1450960922-682003330-1005\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe (User 'Ramsey & Heather')
O4 - HKUS\S-1-5-21-73586283-1450960922-682003330-1005\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe" (User 'Ramsey & Heather')
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20070501/qtinstall.info.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52...pple.com/mickey/us/win/QuickTimeInstaller.exe
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1190164841031
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://www.putfile.com/includes/ImageUploader4-5.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A4110378-789B-455F-AE86-3A1BFC402853} (ZPA_SHVL Object) - http://zone.msn.com/bingame/zpagames/zpa_shvl.cab55579.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab57176.cab
O20 - Winlogon Notify: ddcArSJc - C:\WINDOWS\SYSTEM32\ddcArSJc.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\PcCtlCom.exe
O23 - Service: Trend Micro Protection Against Spyware (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\PcScnSrv.exe
O23 - Service: SQLAgent$SONY_MEDIAMGR - Toshiba Corporation - (no file)
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\tmproxy.exe

--
End of file - 11944 bytes

-- Files created between 2008-05-07 and 2008-06-07 -----------------------------

2008-06-07 09:44:43 92160 --a------ C:\WINDOWS\system32\oepsrcbf.dll
2008-06-07 09:41:44 2560 --a------ C:\WINDOWS\system32\dkxjoabq.exe
2008-06-07 09:39:34 108544 --a------ C:\WINDOWS\system32\kfhcgsqk.dll
2008-06-07 09:39:22 101376 --a------ C:\WINDOWS\system32\uyibarnf.dll
2008-06-07 09:38:41 729773 --ahs---- C:\WINDOWS\system32\dghilUvw.ini2
2008-06-07 09:38:39 347136 --a------ C:\WINDOWS\system32\wvUlihgd.dll
2008-06-07 00:49:58 0 d-------- C:\Program Files\Panda Security
2008-06-07 00:49:57 0 d-------- C:\WINDOWS\LastGood
2008-06-07 00:43:10 1720086 --a------ C:\WINDOWS\system32\TmpA4979000
2008-06-06 23:54:04 2560 --a------ C:\WINDOWS\system32\tlorhmyp.exe
2008-06-06 23:51:03 91648 --a------ C:\WINDOWS\system32\bwspvfdo.dll
2008-06-06 23:48:03 108544 --a------ C:\WINDOWS\system32\nurjlvkc.dll
2008-06-06 23:46:02 100864 --a------ C:\WINDOWS\system32\rovlxmvf.dll
2008-06-06 23:45:01 730193 --ahs---- C:\WINDOWS\system32\RtAIOqss.ini2
2008-06-06 23:44:58 347136 --a------ C:\WINDOWS\system32\ssqOIAtR.dll
2008-06-06 23:38:02 520192 --a------ C:\WINDOWS\system32\wscma2u.exe <Not Verified; YAMAHA CORPORATION; WSC-MA2 (UTF-8)>
2008-06-06 23:38:02 193536 --a------ C:\WINDOWS\system32\atomid.exe
2008-06-06 23:38:02 278528 --a------ C:\WINDOWS\system32\ammpp.dll
2008-06-06 23:38:02 65536 --a------ C:\WINDOWS\system32\a1.dll
2008-06-06 23:38:01 0 d-------- C:\Program Files\AnMing
2008-06-06 23:24:54 91648 -----n--- C:\WINDOWS\system32\rsqaqnww.dll
2008-06-06 23:24:50 2560 --a------ C:\WINDOWS\system32\pdlvybag.exe
2008-06-06 23:23:24 108544 --a------ C:\WINDOWS\system32\mbrhwwxe.dll
2008-06-06 23:23:14 100864 --a------ C:\WINDOWS\system32\woxpuehu.dll
2008-06-04 10:39:41 0 d-------- C:\Program Files\CCleaner
2008-06-03 16:01:18 2560 --a------ C:\WINDOWS\system32\ydiowrli.exe
2008-06-03 16:01:12 133120 --a------ C:\WINDOWS\system32\latmqvub.dll
2008-06-03 15:58:13 115200 -----n--- C:\WINDOWS\system32\urbvopgx.dll
2008-06-03 15:56:37 125952 --a------ C:\WINDOWS\system32\hhensmwu.dll
2008-06-02 14:56:24 0 d-------- C:\Documents and Settings\Mike & Michelle\Application Data\Winamp
2008-06-02 12:13:27 133120 --a------ C:\WINDOWS\system32\bmcooibd.dll
2008-06-02 12:10:07 133120 --a------ C:\WINDOWS\system32\akytaxnx.dll
2008-06-02 12:06:26 125952 --a------ C:\WINDOWS\system32\xlsrolmt.dll
2008-06-01 11:54:58 132096 --a------ C:\WINDOWS\system32\afxjnohw.dll
2008-06-01 11:45:57 126464 --a------ C:\WINDOWS\system32\uxcwxsvy.dll
2008-05-31 11:51:58 132096 --a------ C:\WINDOWS\system32\mqamhoki.dll
2008-05-31 11:45:57 126464 --a------ C:\WINDOWS\system32\ajoaxkft.dll
2008-05-30 12:22:11 0 d-------- C:\Documents and Settings\Mike & Michelle\Application Data\Apple Computer
2008-05-30 11:45:32 134144 --a------ C:\WINDOWS\system32\ddlblrxo.dll
2008-05-30 11:44:20 125440 --a------ C:\WINDOWS\system32\posxinyw.dll
2008-05-28 00:07:54 0 d-------- C:\Program Files\Bodog Poker
2008-05-28 00:07:52 0 d-------- C:\Program Files\Avanquest update
2008-05-28 00:07:43 0 d-------- C:\Program Files\Motorola Phone Tools
2008-05-28 00:07:42 0 d-------- C:\Documents and Settings\Ramsey & Heather\Application Data\InstallShield
2008-05-28 00:07:42 0 d-------- C:\Documents and Settings\All Users\Application Data\BVRP Software
2008-05-28 00:07:37 0 d-------- C:\Media
2008-05-28 00:07:36 0 d-------- C:\WINDOWS\system32\Data
2008-05-28 00:07:35 0 d-------- C:\Program Files\Creative
2008-05-27 19:15:08 7077888 --a------ C:\Documents and Settings\Ramsey & Heather\ntuser.dat
2008-05-27 17:00:47 729648 --ahs---- C:\WINDOWS\system32\RYJlUvut.ini2
2008-05-27 17:00:43 370688 --a------ C:\WINDOWS\system32\tuvUlJYR.dll
2008-05-27 16:55:26 57344 --a------ C:\WINDOWS\system32\ddcArSJc.dll
2008-05-26 14:20:37 0 d-------- C:\Program Files\Winamp
2008-05-26 14:20:37 0 d-------- C:\Documents and Settings\Ramsey & Heather\Application Data\Winamp


-- Find3M Report ---------------------------------------------------------------

2008-06-02 14:28:23 0 d-------- C:\Program Files\SpywareBlaster
2008-05-28 00:07:32 0 d-------- C:\Program Files\MalwareAlarm
2008-05-27 19:16:09 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-05-19 14:29:13 0 d-------- C:\Program Files\Soulseek
2008-05-13 09:52:25 35564 --a------ C:\amt1
2008-05-06 22:41:32 0 d-------- C:\Program Files\QuickTime
2008-04-26 12:57:02 0 d-------- C:\Program Files\Common Files\DVDVideoSoft
2008-04-26 12:57:01 0 d-------- C:\Program Files\Common Files
2008-04-26 12:56:45 0 d-------- C:\Program Files\DVDVideoSoft
2008-04-16 08:20:52 0 d-------- C:\Program Files\Google
2008-04-14 11:43:21 1720086 --a------ C:\WINDOWS\system32\TmpA1810812
2008-04-14 11:42:50 0 d-------- C:\Program Files\ErrorSmart
2008-04-13 00:53:07 0 d-------- C:\Documents and Settings\Mike & Michelle\Application Data\Real
2008-03-09 01:15:33 86528 --a------ C:\WINDOWS\system32\VACFix.exe <Not Verified; S!Ri.URZ; VACFix>


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{087080C2-CE44-4E75-982E-ABB69C63A176}]
05/27/2008 05:00 PM 370688 --a------ C:\WINDOWS\system32\tuvUlJYR.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7d0a3fdf-7293-460e-9e02-844d082eb39b}]
06/07/2008 09:39 AM 108544 --a------ C:\WINDOWS\system32\kfhcgsqk.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BDD714BC-D36C-487B-8142-8BA020FB6535}]
05/27/2008 04:55 PM 57344 --a------ C:\WINDOWS\system32\ddcArSJc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [04/24/2003 05:58 PM]
"diagent"="C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" [04/03/2002 02:01 AM]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [05/11/2000 02:00 AM]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [12/10/2004 01:45 PM C:\WINDOWS\KHALMNPR.Exe]
"pccguide.exe"="C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe" [08/25/2006 12:25 PM]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [01/12/2006 04:40 PM]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [01/15/2008 04:22 AM]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [01/11/2008 11:16 PM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [02/22/2008 04:25 AM]
"TosGbWatcher"="C:\Program Files\TOSHIBA\gigabeat room 3.0\TosGbWatcher.exe" [11/07/2005 03:00 AM]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [03/31/2008 07:31 AM]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [03/28/2008 11:37 PM]
"Windows Sound"="svdhost.exe" [06/13/2007 05:23 AM C:\WINDOWS\system32\svdhost.exe]
"Microsoft WinUpdate"="C:\WINDOWS\system32\msupdte.exe" []
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [04/01/2008 01:49 PM]
"44a07517"="C:\WINDOWS\system32\oepsrcbf.dll" [06/07/2008 09:44 AM]
"BM4793468b"="C:\WINDOWS\system32\uyibarnf.dll" [06/07/2008 09:39 AM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/12/2004 08:56 AM]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [06/01/2006 01:32 PM]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [10/13/2004 11:24 AM]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" []
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" []

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices]
"Windows Sound"=svdhost.exe

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [3/8/2007 10:29:43 PM]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
@=

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{BDD714BC-D36C-487B-8142-8BA020FB6535}"= C:\WINDOWS\system32\ddcArSJc.dll [05/27/2008 04:55 PM 57344]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ddcArSJc]
ddcArSJc.dll 05/27/2008 04:55 PM 57344 C:\WINDOWS\system32\ddcArSJc.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\tuvUlJYR

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
ympcnh ympcnh




-- End of Deckard's System Scanner: finished at 2008-06-07 10:18:35
See less See more
Status
Not open for further replies.
1 - 8 of 8 Posts
Please print the below instructions or copy them to Notepad. Make sure to work through the fixes in the order mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes. Also if you have any programs that may prevent system changes (like Spybot's TeaTimer program, Ad-aware's Ad-Watch, and others), make sure you disable them before doing any of the fixes (or accept the changes for the fix we give you when asked by the programs).

Go to My Computer->Tools (or View)->Folder Options->View tab:
* Under the Hidden files and folders heading, select Show hidden files and folders (it's Show all files for Windows 98).
* Uncheck the Hide protected operating system files (recommended) option.
* Click Yes to confirm and then click OK.
** You may change the above options back after your log is clean. If we ask you to fix something that you use or want to keep, please post back saying that (we don't know every program that exists, so we may tell you to delete a program that we think is bad to keep).

Restart your computer and boot into Safe Mode (if you don't know how, go to http://www.bleepingcomputer.com/forums/index.php?showtutorial=61 ). Make sure to close any internet browsers that may still be open.

Uninstall the following via the Add/Remove Panel (Start->Settings->Control Panel->Add/Remove Programs) if found:

ErrorSmart

Run a scan in HijackThis. Check each of the following if they still exist and hit 'Fix Checked' after you checked the last one:

O2 - BHO: (no name) - {087080C2-CE44-4E75-982E-ABB69C63A176} - C:\WINDOWS\system32\tuvUlJYR.dll
O2 - BHO: {b93be280-d448-20e9-e064-3927fdf3a0d7} - {7d0a3fdf-7293-460e-9e02-844d082eb39b} - C:\WINDOWS\system32\kfhcgsqk.dll
O2 - BHO: (no name) - {BDD714BC-D36C-487B-8142-8BA020FB6535} - C:\WINDOWS\system32\ddcArSJc.dll
O4 - HKLM\..\Run: [Windows Sound] svdhost.exe
O4 - HKLM\..\Run: [Microsoft WinUpdate] C:\WINDOWS\system32\msupdte.exe
O4 - HKLM\..\Run: [44a07517] rundll32.exe "C:\WINDOWS\system32\oepsrcbf.dll",b
O4 - HKLM\..\Run: [BM4793468b] Rundll32.exe "C:\WINDOWS\system32\uyibarnf.dll",s
O4 - HKLM\..\RunServices: [Windows Sound] svdhost.exe
O20 - Winlogon Notify: ddcArSJc - C:\WINDOWS\SYSTEM32\ddcArSJc.dll


Download OTMoveIt2 at http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe
* Save it to your desktop.
* Double-click OTMoveIt2.exe to run it. (Vista users, right click on OTMoveIt2.exe and select Run as an Administrator).
* Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

Code:
C:\WINDOWS\system32\oepsrcbf.dll
C:\WINDOWS\system32\uyibarnf.dll
C:\WINDOWS\system32\svdhost.exe
C:\WINDOWS\system32\oepsrcbf.dll
C:\WINDOWS\system32\dkxjoabq.exe
C:\WINDOWS\system32\kfhcgsqk.dll
C:\WINDOWS\system32\uyibarnf.dll
C:\WINDOWS\system32\dghilUvw.ini2
C:\WINDOWS\system32\wvUlihgd.dll
C:\WINDOWS\system32\TmpA4979000
C:\WINDOWS\system32\tlorhmyp.exe
C:\WINDOWS\system32\bwspvfdo.dll
C:\WINDOWS\system32\nurjlvkc.dll
C:\WINDOWS\system32\rovlxmvf.dll
C:\WINDOWS\system32\RtAIOqss.ini2
C:\WINDOWS\system32\ssqOIAtR.dll
C:\WINDOWS\system32\rsqaqnww.dll
C:\WINDOWS\system32\pdlvybag.exe
C:\WINDOWS\system32\mbrhwwxe.dll
C:\WINDOWS\system32\woxpuehu.dll
C:\WINDOWS\system32\ydiowrli.exe
C:\WINDOWS\system32\latmqvub.dll
C:\WINDOWS\system32\urbvopgx.dll
C:\WINDOWS\system32\hhensmwu.dll
C:\WINDOWS\system32\bmcooibd.dll
C:\WINDOWS\system32\akytaxnx.dll
C:\WINDOWS\system32\xlsrolmt.dll
C:\WINDOWS\system32\afxjnohw.dll
C:\WINDOWS\system32\uxcwxsvy.dll
C:\WINDOWS\system32\mqamhoki.dll
C:\WINDOWS\system32\ajoaxkft.dll
C:\WINDOWS\system32\ddlblrxo.dll
C:\WINDOWS\system32\posxinyw.dll
C:\WINDOWS\system32\RYJlUvut.ini2
C:\WINDOWS\system32\tuvUlJYR.dll
C:\WINDOWS\system32\ddcArSJc.dll
C:\WINDOWS\system32\TmpA1810812
C:\Program Files\ErrorSmart
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\\{BDD714BC-D36C-487B-8142-8BA020FB6535}
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ddcArSJc
* Return to OTMoveIt2. Right click in the Paste List of Files/Folders to Move window (under the Yellow bar) and choose Paste.
* Click the red Moveit! button.
* A log of files and folders moved will be created in the C:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log). Please open this log in Notepad and post its contents in your next reply.
* Close OTMoveIt2.

If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.


Go to http://www.bleepingcomputer.com/combofix/how-to-use-combofix and follow the instructions on how to install the Recovery Console and run ComboFix. Go through all the steps until posting the log part. Post the combofix log here.
See less See more
Alright, I've done what you've instructed. Ran OTMoveIt2 and will post the log first, then I ran ComboFix and will attach it because it's so large. My pc seems to be running better now, search function and media player both work again and no Trend Micro warnings are popping up. However, it is still telling me that it can't turn the security center automatic updates on. It says to go to control panel, then to system, then to click automatic on the automatic updates tab. When I go there, automatic is already checked. Any clue as to what thats all about? Thanx for the help, tech support forum is the best!


OTMoveIt2 Scan ----------


File/Folder C:\WINDOWS\system32\oepsrcbf.dll not found.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\uyibarnf.dll
C:\WINDOWS\system32\uyibarnf.dll NOT unregistered.
C:\WINDOWS\system32\uyibarnf.dll moved successfully.
C:\WINDOWS\system32\svdhost.exe moved successfully.
File/Folder C:\WINDOWS\system32\oepsrcbf.dll not found.
C:\WINDOWS\system32\dkxjoabq.exe moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\kfhcgsqk.dll
C:\WINDOWS\system32\kfhcgsqk.dll NOT unregistered.
C:\WINDOWS\system32\kfhcgsqk.dll moved successfully.
File/Folder C:\WINDOWS\system32\uyibarnf.dll not found.
C:\WINDOWS\system32\dghilUvw.ini2 moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\wvUlihgd.dll
C:\WINDOWS\system32\wvUlihgd.dll NOT unregistered.
C:\WINDOWS\system32\wvUlihgd.dll moved successfully.
C:\WINDOWS\system32\TmpA4979000 moved successfully.
C:\WINDOWS\system32\tlorhmyp.exe moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\bwspvfdo.dll
C:\WINDOWS\system32\bwspvfdo.dll NOT unregistered.
C:\WINDOWS\system32\bwspvfdo.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\system32\nurjlvkc.dll
C:\WINDOWS\system32\nurjlvkc.dll NOT unregistered.
C:\WINDOWS\system32\nurjlvkc.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\rovlxmvf.dll
C:\WINDOWS\system32\rovlxmvf.dll NOT unregistered.
C:\WINDOWS\system32\rovlxmvf.dll moved successfully.
C:\WINDOWS\system32\RtAIOqss.ini2 moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\ssqOIAtR.dll
C:\WINDOWS\system32\ssqOIAtR.dll NOT unregistered.
C:\WINDOWS\system32\ssqOIAtR.dll moved successfully.
File/Folder C:\WINDOWS\system32\rsqaqnww.dll not found.
C:\WINDOWS\system32\pdlvybag.exe moved successfully.
LoadLibrary failed for C:\WINDOWS\system32\mbrhwwxe.dll
C:\WINDOWS\system32\mbrhwwxe.dll NOT unregistered.
C:\WINDOWS\system32\mbrhwwxe.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\woxpuehu.dll
C:\WINDOWS\system32\woxpuehu.dll NOT unregistered.
C:\WINDOWS\system32\woxpuehu.dll moved successfully.
C:\WINDOWS\system32\ydiowrli.exe moved successfully.
LoadLibrary failed for C:\WINDOWS\system32\latmqvub.dll
C:\WINDOWS\system32\latmqvub.dll NOT unregistered.
C:\WINDOWS\system32\latmqvub.dll moved successfully.
File/Folder C:\WINDOWS\system32\urbvopgx.dll not found.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\hhensmwu.dll
C:\WINDOWS\system32\hhensmwu.dll NOT unregistered.
C:\WINDOWS\system32\hhensmwu.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\system32\bmcooibd.dll
C:\WINDOWS\system32\bmcooibd.dll NOT unregistered.
C:\WINDOWS\system32\bmcooibd.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\system32\akytaxnx.dll
C:\WINDOWS\system32\akytaxnx.dll NOT unregistered.
C:\WINDOWS\system32\akytaxnx.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\xlsrolmt.dll
C:\WINDOWS\system32\xlsrolmt.dll NOT unregistered.
C:\WINDOWS\system32\xlsrolmt.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\system32\afxjnohw.dll
C:\WINDOWS\system32\afxjnohw.dll NOT unregistered.
C:\WINDOWS\system32\afxjnohw.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\uxcwxsvy.dll
C:\WINDOWS\system32\uxcwxsvy.dll NOT unregistered.
C:\WINDOWS\system32\uxcwxsvy.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\system32\mqamhoki.dll
C:\WINDOWS\system32\mqamhoki.dll NOT unregistered.
C:\WINDOWS\system32\mqamhoki.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\ajoaxkft.dll
C:\WINDOWS\system32\ajoaxkft.dll NOT unregistered.
C:\WINDOWS\system32\ajoaxkft.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\system32\ddlblrxo.dll
C:\WINDOWS\system32\ddlblrxo.dll NOT unregistered.
C:\WINDOWS\system32\ddlblrxo.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\posxinyw.dll
C:\WINDOWS\system32\posxinyw.dll NOT unregistered.
C:\WINDOWS\system32\posxinyw.dll moved successfully.
C:\WINDOWS\system32\RYJlUvut.ini2 moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\tuvUlJYR.dll
C:\WINDOWS\system32\tuvUlJYR.dll NOT unregistered.
File move failed. C:\WINDOWS\system32\tuvUlJYR.dll scheduled to be moved on reboot.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\ddcArSJc.dll
C:\WINDOWS\system32\ddcArSJc.dll NOT unregistered.
File move failed. C:\WINDOWS\system32\ddcArSJc.dll scheduled to be moved on reboot.
C:\WINDOWS\system32\TmpA1810812 moved successfully.
C:\Program Files\ErrorSmart moved successfully.
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\\{BDD714BC-D36C-487B-8142-8BA020FB6535} >
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\\{BDD714BC-D36C-487B-8142-8BA020FB6535} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BDD714BC-D36C-487B-8142-8BA020FB6535}\ deleted successfully.
< HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ddcArSJc >
Registry key HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ddcArSJc\\ deleted successfully.

OTMoveIt2 by OldTimer - Version 1.0.4.2 log created on 06072008_223716

Files moved on Reboot...
DllUnregisterServer procedure not found in C:\WINDOWS\system32\tuvUlJYR.dll
C:\WINDOWS\system32\tuvUlJYR.dll NOT unregistered.
File move failed. C:\WINDOWS\system32\tuvUlJYR.dll scheduled to be moved on reboot.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\ddcArSJc.dll
C:\WINDOWS\system32\ddcArSJc.dll NOT unregistered.
File move failed. C:\WINDOWS\system32\ddcArSJc.dll scheduled to be moved on reboot.

Attachments

See less See more
Uninstall ErrorSmart and MalwareAlarm via the Add/Remove Programs panel.

Download Malwarebytes ' Anti-Malware at http://www.besttechie.net/tools/mbam-setup.exe or http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html Double-click on mbam-setup.exe to install the application.

* Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform Full Scan, then click Scan.
* The scan may take some time to finish, so please be patient.
* When the scan is complete, click OK, then Show Results to view the results.
* Make sure that everything is checked, and click Remove Selected.
* When disinfection is completed, a log will open in Notepad and you may be prompted to restart (see Extra Note below).
* The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
* Copy & paste the entire report into your next reply.

Extra Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.


Open up your Notepad editor (Start->Run, type in notepad and click OK). Copy the text from the quotebox below into Notepad:
Driver::
ympcnh
File::
C:\WINDOWS\system32\kfhcgsqk.dll
C:\WINDOWS\Tasks\ErrorSmart Scheduled Scan.job
Folder::
C:\Program Files\MalwareAlarm
C:\Documents and Settings\Ramsey & Heather\Application Data\ErrorSmart
C:\Program Files\ErrorSmart\
Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7d0a3fdf-7293-460e-9e02-844d082eb39b}]
Save this as CFScript.txt in the same location as the ComboFix.exe tool.
Drag the CFScript.txt into ComboFix.exe
Follow the prompts. When finished, it shall produce a log for you. Post that log in your next reply.

Note: Do not click on combofix's window while it's running. That may cause it to stall.
See less See more
Followed your instruction, and here are the logs.



Malwarebytes' Anti-Malware 1.15
Database version: 842

2:05:22 PM 6/9/2008
mbam-log-6-9-2008 (14-05-21).txt

Scan type: Full Scan (C:\|F:\|G:\|H:\|)
Objects scanned: 160488
Time elapsed: 1 hour(s), 5 minute(s), 25 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 5
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 15

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\Typelib\{f9fa603d-697c-4900-a950-e54f08324a24} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\nmwegbsf.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Program Files\MalwareAlarm (Rogue.Malware.Alarm) -> Quarantined and deleted successfully.

Files Infected:
C:\QooBox\Quarantine\C\Program Files\JavaCore\UnInstall.exe.vir (Adware.Insider) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\byxqbvil.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\jkkJayWQ.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\tuvUlJYR.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{30E23117-7F1F-408A-B28B-52AF2305E46B}\RP475\A0050971.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{30E23117-7F1F-408A-B28B-52AF2305E46B}\RP475\A0050972.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{30E23117-7F1F-408A-B28B-52AF2305E46B}\RP475\A0051008.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{30E23117-7F1F-408A-B28B-52AF2305E46B}\RP478\A0051910.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{30E23117-7F1F-408A-B28B-52AF2305E46B}\RP478\A0051961.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{30E23117-7F1F-408A-B28B-52AF2305E46B}\RP478\A0051962.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{30E23117-7F1F-408A-B28B-52AF2305E46B}\RP478\A0051987.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\_OTMoveIt\MovedFiles\06072008_223716\WINDOWS\system32\wvUlihgd.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
H:\Ramsey and Heather\My Programs\MP3.To.Ringtone.Gold.v3.16.WinALL.Incl.Keymaker-CORE\CORE10k.EXE (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\MalwareAlarm\MalwareAlarm.lic (Rogue.Malware.Alarm) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\clkcnt.txt (Trojan.Vundo) -> Quarantined and deleted successfully.



------------------------------------------------------------------------




ComboFix 08-06-08.8 - Mike & Michelle 2008-06-09 14:13:45.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1753 [GMT -5:00]
Running from: C:\Documents and Settings\Mike & Michelle\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Mike & Michelle\Desktop\CFScript.txt
* Created a new restore point

FILE ::
C:\WINDOWS\system32\kfhcgsqk.dll
C:\WINDOWS\Tasks\ErrorSmart Scheduled Scan.job
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Ramsey & Heather\Application Data\ErrorSmart
C:\Documents and Settings\Ramsey & Heather\Application Data\ErrorSmart\Log\2008 Apr 14 - 10_53_38 AM_828.log
C:\Documents and Settings\Ramsey & Heather\Application Data\ErrorSmart\Log\2008 Apr 14 - 10_53_44 AM_062.log
C:\Documents and Settings\Ramsey & Heather\Application Data\ErrorSmart\Log\2008 Apr 14 - 11_13_34 AM_921.log
C:\Documents and Settings\Ramsey & Heather\Application Data\ErrorSmart\Log\2008 Apr 14 - 11_13_40 AM_062.log
C:\Documents and Settings\Ramsey & Heather\Application Data\ErrorSmart\Registry Backups\2008-03-25_09-05-19.reg
C:\Documents and Settings\Ramsey & Heather\Application Data\ErrorSmart\Registry Backups\2008-03-25_09-21-47.reg
C:\Documents and Settings\Ramsey & Heather\Application Data\ErrorSmart\Registry Backups\2008-03-25_09-24-52.reg
C:\Documents and Settings\Ramsey & Heather\Application Data\ErrorSmart\Registry Backups\2008-03-27_11-43-47.reg
C:\Documents and Settings\Ramsey & Heather\Application Data\ErrorSmart\Registry Backups\2008-03-28_12-06-18.reg
C:\Documents and Settings\Ramsey & Heather\Application Data\ErrorSmart\Registry Backups\2008-04-01_08-53-41.reg
C:\Documents and Settings\Ramsey & Heather\Application Data\ErrorSmart\Registry Backups\2008-04-02_17-42-26.reg
C:\Documents and Settings\Ramsey & Heather\Application Data\ErrorSmart\Registry Backups\2008-04-05_22-18-49.reg
C:\Documents and Settings\Ramsey & Heather\Application Data\ErrorSmart\Registry Backups\2008-04-09_11-14-07.reg

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_YMPCNH
-------\Service_ympcnh


((((((((((((((((((((((((( Files Created from 2008-05-09 to 2008-06-09 )))))))))))))))))))))))))))))))
.

2008-06-09 11:17 . 2008-06-09 11:17 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-09 11:17 . 2008-06-09 11:17 <DIR> d-------- C:\Documents and Settings\Mike & Michelle\Application Data\Malwarebytes
2008-06-09 11:17 . 2008-06-09 11:17 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-09 11:17 . 2008-06-05 16:04 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-09 11:17 . 2008-06-05 16:04 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-07 22:37 . 2008-06-07 22:37 <DIR> d-------- C:\_OTMoveIt
2008-06-07 00:49 . 2008-06-07 00:50 <DIR> d-------- C:\Program Files\Panda Security
2008-06-06 23:38 . 2008-06-06 23:38 <DIR> d-------- C:\Program Files\AnMing
2008-06-06 23:38 . 2004-08-04 20:46 520,192 --a------ C:\WINDOWS\system32\wscma2u.exe
2008-06-06 23:38 . 2005-10-21 20:20 278,528 --a------ C:\WINDOWS\system32\ammpp.dll
2008-06-06 23:38 . 2003-07-17 23:49 193,536 --a------ C:\WINDOWS\system32\atomid.exe
2008-06-06 23:38 . 2005-07-13 15:13 65,536 --a------ C:\WINDOWS\system32\a1.dll
2008-06-06 23:38 . 2005-09-18 13:17 61,440 --a------ C:\WINDOWS\system32\anming.ocx
2008-06-04 10:39 . 2008-06-04 10:39 <DIR> d-------- C:\Program Files\CCleaner
2008-06-02 14:56 . 2008-06-04 10:39 <DIR> d-------- C:\Documents and Settings\Mike & Michelle\Application Data\Winamp
2008-05-30 12:22 . 2008-05-30 12:22 <DIR> d-------- C:\Documents and Settings\Mike & Michelle\Application Data\Apple Computer
2008-05-28 00:07 . 2008-05-28 00:07 <DIR> d-------- C:\WINDOWS\system32\Data
2008-05-28 00:07 . 2008-05-28 00:07 <DIR> d-------- C:\Program Files\Motorola Phone Tools
2008-05-28 00:07 . 2008-05-28 00:07 <DIR> d-------- C:\Program Files\Creative
2008-05-28 00:07 . 2008-05-28 00:07 <DIR> d-------- C:\Program Files\Bodog Poker
2008-05-28 00:07 . 2008-05-28 00:07 <DIR> d-------- C:\Program Files\Avanquest update
2008-05-28 00:07 . 2008-05-28 00:07 <DIR> d-------- C:\Media
2008-05-28 00:07 . 2008-05-28 00:07 <DIR> d-------- C:\Documents and Settings\Ramsey & Heather\Application Data\InstallShield
2008-05-28 00:07 . 2008-05-28 00:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\BVRP Software
2008-05-26 14:20 . 2008-05-26 14:21 <DIR> d-------- C:\Program Files\Winamp
2008-05-26 14:20 . 2008-05-26 14:40 <DIR> d-------- C:\Documents and Settings\Ramsey & Heather\Application Data\Winamp

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-08 17:56 --------- d-----w C:\Documents and Settings\Ramsey & Heather\Application Data\DNA
2008-06-08 05:14 --------- d-----w C:\Documents and Settings\Ramsey & Heather\Application Data\uTorrent
2008-06-02 19:29 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-02 19:28 --------- d-----w C:\Program Files\SpywareBlaster
2008-05-28 00:16 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-19 19:29 --------- d-----w C:\Program Files\Soulseek
2008-05-07 03:41 --------- d-----w C:\Program Files\QuickTime
2008-05-02 21:22 205,328 ----a-w C:\WINDOWS\system32\drivers\tmxpflt.sys
2008-05-02 21:21 36,368 ----a-w C:\WINDOWS\system32\drivers\tmpreflt.sys
2008-05-02 21:17 1,169,240 ----a-w C:\WINDOWS\system32\drivers\VsapiNT.sys
2008-04-26 17:57 --------- d-----w C:\Program Files\Common Files\DVDVideoSoft
2008-04-26 17:56 --------- d-----w C:\Program Files\DVDVideoSoft
2008-04-26 17:51 --------- d-----w C:\Documents and Settings\Ramsey & Heather\Application Data\FLV Extract
2008-04-26 17:48 --------- d-----w C:\Documents and Settings\Ramsey & Heather\Application Data\dvdcss
2008-04-16 13:20 --------- d-----w C:\Program Files\Google
2007-07-06 22:11 47,360 ----a-w C:\Documents and Settings\Ramsey & Heather\Application Data\pcouffin.sys
.

((((((((((((((((((((((((((((( snapshot_2008-06-07_23.03.09.85 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-08 03:53:41 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-09 19:18:34 2,048 --s-a-w C:\WINDOWS\bootstat.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-12 08:56 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-06-01 13:32 94208]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24 1694208]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [ ]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2003-04-24 17:58 4616192]
"diagent"="C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" [2002-04-03 02:01 135264]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-11 02:00 90112]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2004-12-10 13:45 49152 C:\WINDOWS\KHALMNPR.Exe]
"pccguide.exe"="C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe" [2006-08-25 12:25 3112960]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 16:40 155648]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 04:22 267048]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"TosGbWatcher"="C:\Program Files\TOSHIBA\gigabeat room 3.0\TosGbWatcher.exe" [2005-11-07 03:00 118837]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-03-31 07:31 185896]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-03-28 23:37 413696]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-04-01 13:49 36352]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2007-03-08 22:29:43 434176]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.ctmp3"= C:\WINDOWS\system32\ctmp3.acm

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\uTorrent\\utorrent.exe"=
"C:\\Program Files\\Soulseek\\slsk.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\DNA\\btdna.exe"=

R0 Spssys;Toshiba SPS Service;C:\WINDOWS\system32\drivers\spssys.sys [2004-05-07 21:56]
R2 zumbus;Zune Bus Enumerator Driver;C:\WINDOWS\system32\DRIVERS\zumbus.sys [2007-11-15 22:38]
S3 BRGSp50;BRGSp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\BRGSp50.sys [2005-06-08 18:44]
S3 motccgp;Motorola USB Composite Device Driver;C:\WINDOWS\system32\DRIVERS\motccgp.sys [2007-04-02 22:13]
S3 motccgpfl;MotCcgpFlService;C:\WINDOWS\system32\DRIVERS\motccgpfl.sys [2007-01-23 20:03]
S3 MotDev;Motorola Inc. USB Device;C:\WINDOWS\system32\DRIVERS\motodrv.sys [2006-12-14 11:27]
S3 ZD1211BU(ZyDAS);ZyDAS ZD1211B IEEE 802.11 b+g Wireless LAN Driver (USB)(ZyDAS);C:\WINDOWS\system32\DRIVERS\zd1211Bu.sys [2005-08-17 14:43]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
ympcnh REG_MULTI_SZ ympcnh

.
Contents of the 'Scheduled Tasks' folder
"2008-06-04 15:20:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-06-09 19:21:41 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-09 14:19:09
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\PcCtlCom.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\tmproxy.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Trend Micro\Internet Security 2007\PcScnSrv.exe
.
**************************************************************************
.
Completion time: 2008-06-09 14:22:09 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-09 19:21:59
ComboFix2.txt 2008-06-08 04:03:36
ComboFix3.txt 2008-03-19 06:41:17
ComboFix4.txt 2008-03-18 04:27:05

Pre-Run: 10,262,994,944 bytes free
Post-Run: 10,348,109,824 bytes free

183 --- E O F --- 2008-05-26 06:23:36
See less See more
I see you are using BitTorrent programs there. I don't recommend using these as they will help contribute to malware infections...

Do you know what this program is used for? -> C:\Program Files\AnMing

If you know what that program is for, you may leave it alone.

Good job. Your log is clean.

To help prevent future spyware infections, read the Anti-Spyware Tutorial and use the tools provided.

Are there any problems now? If none, go to Start->Run, copy/paste in combofix /u and hit OK to remove it. You should be set to go.
See less See more
Thanx again, for your help.

My pc still will not let me turn on automatic updates for some reason. Thats the only issue left to resolve.

One more question, I have 3 separate profiles on this pc so should I have done scans on each one or did running them on the admin profile scan the others too?
Go to Start->Run and copy/paste each of the following lines (hitting OK after each line):

regsvr32 wuapi.dll
regsvr32 wuaueng.dll
regsvr32 atl.dll
regsvr32 wucltui.dll
regsvr32 wups.dll

Just copy/paste and hit OK. Then go to Start->Run...repeat and rinse.

See if that fixes the issue.

Usually it should scan all 3 user accounts on the computer. You can login to them to verify they are clean :grin:
See less See more
1 - 8 of 8 Posts
Status
Not open for further replies.
Top